lmoreno092
Posts: 10 +0
so last week my computer froze and when i tried to restart it windows started and said it could not load. so i did a system recovery and everything is working just fine but now i cannot load usaa.com. i can use any other website except this one. this is my bank so i figured that it might have a virus that and everytime i go to usaa.com my computer freezes and i have to hold the power button to restart. here are my malware files gmer did not work for me it just has a blank file and the dds
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7373
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
8/4/2011 4:53:21 PM
mbam-log-2011-08-04 (16-53-21).txt
Scan type: Quick scan
Objects scanned: 169290
Time elapsed: 2 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
.
DDS (Ver_2011-06-23.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385
Run by 123 at 17:14:01 on 2011-08-04
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3836.2524 [GMT -7:00]
.
AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\taskeng.exe
c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtblfs.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cnnb
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: hpBHO Class: {abd3b5e1-b268-407b-a150-2641dab8d898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime
mRun: [Corel File Shell Monitor] C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-system: WallpaperStyle = 2
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
TCP: DhcpNameServer = 168.192.1.1 168.95.1.1
TCP: Interfaces\{8CD757CC-7057-4116-868C-33E914BAD8BC} : DhcpNameServer = 168.192.1.1 168.95.1.1
AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
BHO-X64: IEVkbdBHO - No File
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: hpBHO Class: {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll
BHO-X64: HelloWorldBHO - No File
BHO-X64: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
BHO-X64: link filter bho - No File
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: Microsoft Live Search Toolbar: {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime
mRun-x64: [Corel File Shell Monitor] C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
mRun-x64: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun-x64: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
AppInit_DLLs-X64: C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
.
============= SERVICES / DRIVERS ===============
.
R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-7-18 146816]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2011/08/03 20:00:12];C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2011-8-3 146928]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2011-8-3 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --> C:\Windows\system32\Hpservice.exe [?]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-8-4 366640]
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-8-14 228408]
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys --> C:\Windows\system32\DRIVERS\enecir.sys [?]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [2010-11-2 365336]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
.
=============== Created Last 30 ================
.
2011-08-04 23:26:39 -------- d-----r- C:\Program Files (x86)\Skype
2011-08-04 23:16:24 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9BC96B9A-EFFC-4E7E-B867-44750C4CFE31}\mpengine.dll
2011-08-04 18:24:45 -------- d-----w- C:\Program Files (x86)\Kaspersky Lab
2011-08-04 18:24:44 -------- d-----w- C:\ProgramData\Kaspersky Lab
2011-08-04 18:22:56 -------- d-----w- C:\ProgramData\Kaspersky Lab Setup Files
2011-08-04 13:17:15 367104 ----a-w- C:\Windows\System32\wcncsvc.dll
2011-08-04 13:17:15 276992 ----a-w- C:\Windows\SysWow64\wcncsvc.dll
2011-08-04 13:04:42 311808 ----a-w- C:\Windows\System32\msv1_0.dll
2011-08-04 13:04:42 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2011-08-04 12:49:18 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2011-08-04 12:49:18 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2011-08-04 12:49:18 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2011-08-04 12:49:18 444752 ----a-w- C:\Windows\System32\mscoree.dll
2011-08-04 12:49:18 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2011-08-04 12:49:18 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2011-08-04 12:49:18 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2011-08-04 12:49:18 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2011-08-04 12:49:18 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2011-08-04 12:49:18 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2011-08-04 12:40:40 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
2011-08-04 12:40:40 184832 ----a-w- C:\Windows\System32\drivers\usbvideo.sys
2011-08-04 12:37:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-04 12:36:55 2870272 ----a-w- C:\Windows\explorer.exe
2011-08-04 12:35:58 633856 ----a-w- C:\Windows\System32\comctl32.dll
2011-08-04 12:35:57 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll
2011-08-04 12:35:53 612352 ----a-w- C:\Windows\System32\vbscript.dll
2011-08-04 12:35:53 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2011-08-04 12:35:50 82944 ----a-w- C:\Windows\SysWow64\iccvid.dll
2011-08-04 12:35:23 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-08-04 12:35:23 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-08-04 12:35:02 84992 ----a-w- C:\Windows\System32\asycfilt.dll
2011-08-04 12:35:02 67584 ----a-w- C:\Windows\SysWow64\asycfilt.dll
2011-08-04 12:35:00 102400 ----a-w- C:\Windows\System32\drivers\dfsc.sys
2011-08-04 12:33:52 46592 ----a-w- C:\Windows\System32\msasn1.dll
2011-08-04 12:32:53 404992 ----a-w- C:\Windows\System32\umpnpmgr.dll
2011-08-04 12:32:53 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
2011-08-04 12:32:53 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-08-04 12:32:52 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2011-08-04 12:32:52 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
2011-08-04 12:19:15 720896 ----a-w- C:\Windows\System32\odbc32.dll
2011-08-04 12:19:14 987136 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2011-08-04 12:19:14 573440 ----a-w- C:\Windows\SysWow64\odbc32.dll
2011-08-04 12:19:14 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2011-08-04 12:19:14 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2011-08-04 12:19:14 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2011-08-04 12:19:14 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2011-08-04 12:19:14 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2011-08-04 12:19:14 1425408 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2011-08-04 12:19:13 208896 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2011-08-04 12:15:09 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2011-08-04 12:15:09 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2011-08-04 12:14:57 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2011-08-04 12:14:56 112000 ----a-w- C:\Windows\System32\consent.exe
2011-08-04 12:08:00 -------- d-sh--w- C:\$RECYCLE.BIN
2011-08-04 12:05:49 601424 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9F831F01-0853-43EA-8DB0-AF3663CD3FA1}\gapaengine.dll
2011-08-04 12:04:54 -------- d-----w- C:\Users\123\AppData\Local\Adobe
2011-08-04 12:03:43 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-08-04 12:03:35 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-08-04 12:03:24 374664 ----a-w- C:\Windows\System32\drivers\netio.sys
2011-08-04 10:12:21 8578896 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5C0A4382-19D9-4E6B-997C-9F1AE4327651}\mpengine.dll
2011-08-04 10:12:18 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-08-04 09:04:57 -------- d-----w- C:\Users\123\AppData\Roaming\Malwarebytes
2011-08-04 09:04:23 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-04 09:04:22 -------- d-----w- C:\ProgramData\Malwarebytes
2011-08-04 09:04:19 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-04 09:04:19 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-08-04 09:03:23 -------- d-----w- C:\Users\123\AppData\Roaming\SUPERAntiSpyware.com
2011-08-04 09:03:05 -------- d-----w- C:\ProgramData\!SASCORE
2011-08-04 09:03:00 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-08-04 09:03:00 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2011-08-04 08:59:30 388096 ----a-r- C:\Users\123\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-08-04 08:59:28 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-08-04 05:26:21 -------- d-----w- C:\Users\123\AppData\Roaming\AVG10
2011-08-04 05:24:51 -------- d--h--w- C:\ProgramData\Common Files
2011-08-04 05:24:07 -------- d-----w- C:\Windows\System32\drivers\AVG
2011-08-04 05:24:07 -------- d-----w- C:\ProgramData\AVG10
2011-08-04 05:23:30 -------- d-----w- C:\Program Files (x86)\AVG
2011-08-04 05:14:08 -------- d-----w- C:\ProgramData\MFAData
2011-08-04 04:06:30 -------- d-----w- C:\Users\123\AppData\Roaming\Panda Security
2011-08-04 04:05:46 -------- d-----w- C:\ProgramData\Panda Security
2011-08-04 04:05:46 -------- d-----w- C:\Program Files (x86)\Panda Security
2011-08-04 04:05:26 -------- d-----w- C:\temp
2011-08-04 04:04:59 -------- d-----w- C:\Users\123\AppData\Roaming\HpUpdate
2011-08-04 03:56:46 -------- d-----w- C:\Users\123\AppData\Local\ATI
2011-08-04 03:56:12 -------- d-----w- C:\Users\123\AppData\Local\VirtualStore
2011-08-04 03:56:05 -------- d-----w- C:\Users\123\AppData\Local\Hewlett-Packard_Company
2011-08-04 03:56:01 -------- d-----w- C:\Users\123\AppData\Roaming\hpqlog
2011-08-04 03:53:03 -------- d-----w- C:\Users\123\AppData\Roaming\HP TCS
2011-08-04 03:52:54 220672 ----a-w- C:\Windows\System32\wintrust.dll
2011-08-04 03:52:54 172032 ----a-w- C:\Windows\SysWow64\wintrust.dll
2011-08-04 03:52:52 139264 ----a-w- C:\Windows\System32\cabview.dll
2011-08-04 03:52:52 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
2011-08-04 03:43:21 -------- d-----w- C:\ProgramData\Recovery
2011-08-04 03:40:20 -------- d-----w- C:\Windows\ehome
2011-08-04 03:23:34 140066664 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\wlc3468.tmp
2011-08-04 03:20:39 -------- d-----w- C:\ProgramData\Corel
2011-08-04 03:20:39 -------- d-----w- C:\Program Files (x86)\Common Files\Protexis
2011-08-04 03:20:39 -------- d-----w- C:\Program Files (x86)\Common Files\Corel
2011-08-04 03:17:39 368640 ----a-w- C:\Windows\System32\HP MediaSmart Demo.scr
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2011-08-04 03:15:30 -------- d-----w- C:\Program Files (x86)\Windows Media Components
2011-08-04 03:13:24 -------- d-----w- C:\Program Files (x86)\Common Files\Ulead Systems
2011-08-04 03:13:20 -------- d-----w- C:\Program Files (x86)\Corel
2011-08-04 03:11:13 -------- d-----w- C:\Program Files (x86)\Sling Media
2011-08-04 02:55:07 -------- d-----w- C:\Windows\Hewlett-Packard
2011-08-04 02:54:31 68608 ----a-w- C:\Windows\System32\AESTAR64.dll
2011-08-04 02:54:31 436224 ----a-w- C:\Windows\System32\AESTEC64.dll
2011-08-04 02:54:30 160768 ----a-w- C:\Windows\System32\AESTAC64.dll
2011-08-04 02:54:29 90624 ----a-w- C:\Windows\System32\AESTCo64.dll
2011-08-04 02:54:29 564224 ----a-w- C:\Windows\System32\idt64mp1.exe
2011-08-04 02:54:29 450048 ----a-w- C:\Windows\sttray64.exe
2011-08-04 02:54:29 3593216 ----a-w- C:\Windows\System32\stlang64.dll
2011-08-04 02:54:29 12158464 ----a-w- C:\Windows\System32\idtcpl64.cpl
2011-08-04 02:54:27 -------- d-----w- C:\Windows\System32\SRSLabs
2011-08-04 02:53:54 209920 ----a-w- C:\Windows\System32\staco64.dll
2011-08-04 02:53:53 604672 ------w- C:\Windows\System32\stapi64.dll
2011-08-04 02:53:53 487936 ----a-w- C:\Windows\System32\drivers\stwrt64.sys
2011-08-04 02:53:53 431616 ----a-w- C:\Windows\System32\stcplx64.dll
2011-08-04 02:53:53 1431552 ----a-w- C:\Windows\System32\stapo64.dll
2011-08-04 02:53:43 -------- d-----w- C:\Program Files\IDT
2011-08-04 02:53:15 -------- d-----w- C:\Program Files (x86)\Atheros
2011-08-04 02:53:10 -------- d-----w- C:\ProgramData\Atheros
2011-08-04 02:52:43 67584 ----a-w- C:\Windows\System32\RtNicProp64.dll
2011-08-04 02:52:43 215040 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2011-08-04 02:52:34 36408 ----a-w- C:\Windows\System32\drivers\usbfilter.sys
2011-08-04 02:52:33 -------- d-----w- C:\Program Files (x86)\AMD
2011-08-04 02:52:22 7347200 ----a-w- C:\Windows\System32\RTSUSTORicon.dll
2011-08-04 02:52:12 -------- d-----w- C:\Program Files (x86)\Realtek
2011-08-04 02:51:54 61440 ------w- C:\Windows\SysWow64\agrsmdel.exe
2011-08-04 02:51:54 14848 ------w- C:\Windows\SysWow64\agrsco64.dll
2011-08-04 02:51:54 13824 ------w- C:\Windows\SysWow64\agrscoin.dll
2011-08-04 02:51:49 -------- d-----w- C:\Program Files\LSI SoftModem
2011-08-04 02:51:44 -------- d-----w- C:\Windows\Options
2011-08-04 02:51:32 -------- d-----w- C:\Program Files\Synaptics
2011-08-04 02:49:27 -------- d-----w- C:\Program Files\ATI
2011-08-04 02:49:25 -------- d-----w- C:\Program Files (x86)\ATI Technologies
.
==================== Find3M ====================
.
2011-06-11 02:56:44 3134464 ----a-w- C:\Windows\System32\win32k.sys
2011-06-02 06:45:22 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-06-02 06:45:22 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-06-02 06:45:22 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-06-02 06:44:54 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-02 06:42:37 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-06-02 06:39:54 422400 ----a-w- C:\Windows\System32\KernelBase.dll
2011-06-02 06:35:56 338944 ----a-w- C:\Windows\System32\conhost.exe
2011-06-02 05:59:44 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-06-02 05:56:28 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-06-02 05:56:06 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-06-02 05:54:51 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-06-02 05:54:50 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-06-02 03:51:00 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-06-02 03:50:59 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-06-02 03:45:49 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-06-02 03:45:49 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-02 03:45:49 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-06-02 03:45:49 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-05-28 03:25:16 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-05-28 03:00:02 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 17:14:51.45 ===============
.
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7373
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
8/4/2011 4:53:21 PM
mbam-log-2011-08-04 (16-53-21).txt
Scan type: Quick scan
Objects scanned: 169290
Time elapsed: 2 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
.
DDS (Ver_2011-06-23.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385
Run by 123 at 17:14:01 on 2011-08-04
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3836.2524 [GMT -7:00]
.
AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\taskeng.exe
c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtblfs.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cnnb
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: hpBHO Class: {abd3b5e1-b268-407b-a150-2641dab8d898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime
mRun: [Corel File Shell Monitor] C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-system: WallpaperStyle = 2
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
TCP: DhcpNameServer = 168.192.1.1 168.95.1.1
TCP: Interfaces\{8CD757CC-7057-4116-868C-33E914BAD8BC} : DhcpNameServer = 168.192.1.1 168.95.1.1
AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
BHO-X64: IEVkbdBHO - No File
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: hpBHO Class: {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll
BHO-X64: HelloWorldBHO - No File
BHO-X64: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
BHO-X64: link filter bho - No File
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: Microsoft Live Search Toolbar: {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime
mRun-x64: [Corel File Shell Monitor] C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
mRun-x64: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun-x64: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
AppInit_DLLs-X64: C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
.
============= SERVICES / DRIVERS ===============
.
R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-7-18 146816]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2011/08/03 20:00:12];C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2011-8-3 146928]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2011-8-3 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --> C:\Windows\system32\Hpservice.exe [?]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-8-4 366640]
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-8-14 228408]
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys --> C:\Windows\system32\DRIVERS\enecir.sys [?]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [2010-11-2 365336]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
.
=============== Created Last 30 ================
.
2011-08-04 23:26:39 -------- d-----r- C:\Program Files (x86)\Skype
2011-08-04 23:16:24 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9BC96B9A-EFFC-4E7E-B867-44750C4CFE31}\mpengine.dll
2011-08-04 18:24:45 -------- d-----w- C:\Program Files (x86)\Kaspersky Lab
2011-08-04 18:24:44 -------- d-----w- C:\ProgramData\Kaspersky Lab
2011-08-04 18:22:56 -------- d-----w- C:\ProgramData\Kaspersky Lab Setup Files
2011-08-04 13:17:15 367104 ----a-w- C:\Windows\System32\wcncsvc.dll
2011-08-04 13:17:15 276992 ----a-w- C:\Windows\SysWow64\wcncsvc.dll
2011-08-04 13:04:42 311808 ----a-w- C:\Windows\System32\msv1_0.dll
2011-08-04 13:04:42 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2011-08-04 12:49:18 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2011-08-04 12:49:18 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2011-08-04 12:49:18 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2011-08-04 12:49:18 444752 ----a-w- C:\Windows\System32\mscoree.dll
2011-08-04 12:49:18 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2011-08-04 12:49:18 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2011-08-04 12:49:18 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2011-08-04 12:49:18 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2011-08-04 12:49:18 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2011-08-04 12:49:18 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2011-08-04 12:40:40 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
2011-08-04 12:40:40 184832 ----a-w- C:\Windows\System32\drivers\usbvideo.sys
2011-08-04 12:37:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-04 12:36:55 2870272 ----a-w- C:\Windows\explorer.exe
2011-08-04 12:35:58 633856 ----a-w- C:\Windows\System32\comctl32.dll
2011-08-04 12:35:57 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll
2011-08-04 12:35:53 612352 ----a-w- C:\Windows\System32\vbscript.dll
2011-08-04 12:35:53 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2011-08-04 12:35:50 82944 ----a-w- C:\Windows\SysWow64\iccvid.dll
2011-08-04 12:35:23 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-08-04 12:35:23 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-08-04 12:35:02 84992 ----a-w- C:\Windows\System32\asycfilt.dll
2011-08-04 12:35:02 67584 ----a-w- C:\Windows\SysWow64\asycfilt.dll
2011-08-04 12:35:00 102400 ----a-w- C:\Windows\System32\drivers\dfsc.sys
2011-08-04 12:33:52 46592 ----a-w- C:\Windows\System32\msasn1.dll
2011-08-04 12:32:53 404992 ----a-w- C:\Windows\System32\umpnpmgr.dll
2011-08-04 12:32:53 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
2011-08-04 12:32:53 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-08-04 12:32:52 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2011-08-04 12:32:52 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
2011-08-04 12:19:15 720896 ----a-w- C:\Windows\System32\odbc32.dll
2011-08-04 12:19:14 987136 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2011-08-04 12:19:14 573440 ----a-w- C:\Windows\SysWow64\odbc32.dll
2011-08-04 12:19:14 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2011-08-04 12:19:14 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2011-08-04 12:19:14 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2011-08-04 12:19:14 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2011-08-04 12:19:14 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2011-08-04 12:19:14 1425408 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2011-08-04 12:19:13 208896 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2011-08-04 12:15:09 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2011-08-04 12:15:09 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2011-08-04 12:14:57 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2011-08-04 12:14:56 112000 ----a-w- C:\Windows\System32\consent.exe
2011-08-04 12:08:00 -------- d-sh--w- C:\$RECYCLE.BIN
2011-08-04 12:05:49 601424 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9F831F01-0853-43EA-8DB0-AF3663CD3FA1}\gapaengine.dll
2011-08-04 12:04:54 -------- d-----w- C:\Users\123\AppData\Local\Adobe
2011-08-04 12:03:43 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-08-04 12:03:35 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-08-04 12:03:24 374664 ----a-w- C:\Windows\System32\drivers\netio.sys
2011-08-04 10:12:21 8578896 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5C0A4382-19D9-4E6B-997C-9F1AE4327651}\mpengine.dll
2011-08-04 10:12:18 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-08-04 09:04:57 -------- d-----w- C:\Users\123\AppData\Roaming\Malwarebytes
2011-08-04 09:04:23 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-04 09:04:22 -------- d-----w- C:\ProgramData\Malwarebytes
2011-08-04 09:04:19 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-04 09:04:19 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-08-04 09:03:23 -------- d-----w- C:\Users\123\AppData\Roaming\SUPERAntiSpyware.com
2011-08-04 09:03:05 -------- d-----w- C:\ProgramData\!SASCORE
2011-08-04 09:03:00 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-08-04 09:03:00 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2011-08-04 08:59:30 388096 ----a-r- C:\Users\123\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-08-04 08:59:28 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-08-04 05:26:21 -------- d-----w- C:\Users\123\AppData\Roaming\AVG10
2011-08-04 05:24:51 -------- d--h--w- C:\ProgramData\Common Files
2011-08-04 05:24:07 -------- d-----w- C:\Windows\System32\drivers\AVG
2011-08-04 05:24:07 -------- d-----w- C:\ProgramData\AVG10
2011-08-04 05:23:30 -------- d-----w- C:\Program Files (x86)\AVG
2011-08-04 05:14:08 -------- d-----w- C:\ProgramData\MFAData
2011-08-04 04:06:30 -------- d-----w- C:\Users\123\AppData\Roaming\Panda Security
2011-08-04 04:05:46 -------- d-----w- C:\ProgramData\Panda Security
2011-08-04 04:05:46 -------- d-----w- C:\Program Files (x86)\Panda Security
2011-08-04 04:05:26 -------- d-----w- C:\temp
2011-08-04 04:04:59 -------- d-----w- C:\Users\123\AppData\Roaming\HpUpdate
2011-08-04 03:56:46 -------- d-----w- C:\Users\123\AppData\Local\ATI
2011-08-04 03:56:12 -------- d-----w- C:\Users\123\AppData\Local\VirtualStore
2011-08-04 03:56:05 -------- d-----w- C:\Users\123\AppData\Local\Hewlett-Packard_Company
2011-08-04 03:56:01 -------- d-----w- C:\Users\123\AppData\Roaming\hpqlog
2011-08-04 03:53:03 -------- d-----w- C:\Users\123\AppData\Roaming\HP TCS
2011-08-04 03:52:54 220672 ----a-w- C:\Windows\System32\wintrust.dll
2011-08-04 03:52:54 172032 ----a-w- C:\Windows\SysWow64\wintrust.dll
2011-08-04 03:52:52 139264 ----a-w- C:\Windows\System32\cabview.dll
2011-08-04 03:52:52 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
2011-08-04 03:43:21 -------- d-----w- C:\ProgramData\Recovery
2011-08-04 03:40:20 -------- d-----w- C:\Windows\ehome
2011-08-04 03:23:34 140066664 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\wlc3468.tmp
2011-08-04 03:20:39 -------- d-----w- C:\ProgramData\Corel
2011-08-04 03:20:39 -------- d-----w- C:\Program Files (x86)\Common Files\Protexis
2011-08-04 03:20:39 -------- d-----w- C:\Program Files (x86)\Common Files\Corel
2011-08-04 03:17:39 368640 ----a-w- C:\Windows\System32\HP MediaSmart Demo.scr
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2011-08-04 03:17:21 131072 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2011-08-04 03:15:30 -------- d-----w- C:\Program Files (x86)\Windows Media Components
2011-08-04 03:13:24 -------- d-----w- C:\Program Files (x86)\Common Files\Ulead Systems
2011-08-04 03:13:20 -------- d-----w- C:\Program Files (x86)\Corel
2011-08-04 03:11:13 -------- d-----w- C:\Program Files (x86)\Sling Media
2011-08-04 02:55:07 -------- d-----w- C:\Windows\Hewlett-Packard
2011-08-04 02:54:31 68608 ----a-w- C:\Windows\System32\AESTAR64.dll
2011-08-04 02:54:31 436224 ----a-w- C:\Windows\System32\AESTEC64.dll
2011-08-04 02:54:30 160768 ----a-w- C:\Windows\System32\AESTAC64.dll
2011-08-04 02:54:29 90624 ----a-w- C:\Windows\System32\AESTCo64.dll
2011-08-04 02:54:29 564224 ----a-w- C:\Windows\System32\idt64mp1.exe
2011-08-04 02:54:29 450048 ----a-w- C:\Windows\sttray64.exe
2011-08-04 02:54:29 3593216 ----a-w- C:\Windows\System32\stlang64.dll
2011-08-04 02:54:29 12158464 ----a-w- C:\Windows\System32\idtcpl64.cpl
2011-08-04 02:54:27 -------- d-----w- C:\Windows\System32\SRSLabs
2011-08-04 02:53:54 209920 ----a-w- C:\Windows\System32\staco64.dll
2011-08-04 02:53:53 604672 ------w- C:\Windows\System32\stapi64.dll
2011-08-04 02:53:53 487936 ----a-w- C:\Windows\System32\drivers\stwrt64.sys
2011-08-04 02:53:53 431616 ----a-w- C:\Windows\System32\stcplx64.dll
2011-08-04 02:53:53 1431552 ----a-w- C:\Windows\System32\stapo64.dll
2011-08-04 02:53:43 -------- d-----w- C:\Program Files\IDT
2011-08-04 02:53:15 -------- d-----w- C:\Program Files (x86)\Atheros
2011-08-04 02:53:10 -------- d-----w- C:\ProgramData\Atheros
2011-08-04 02:52:43 67584 ----a-w- C:\Windows\System32\RtNicProp64.dll
2011-08-04 02:52:43 215040 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2011-08-04 02:52:34 36408 ----a-w- C:\Windows\System32\drivers\usbfilter.sys
2011-08-04 02:52:33 -------- d-----w- C:\Program Files (x86)\AMD
2011-08-04 02:52:22 7347200 ----a-w- C:\Windows\System32\RTSUSTORicon.dll
2011-08-04 02:52:12 -------- d-----w- C:\Program Files (x86)\Realtek
2011-08-04 02:51:54 61440 ------w- C:\Windows\SysWow64\agrsmdel.exe
2011-08-04 02:51:54 14848 ------w- C:\Windows\SysWow64\agrsco64.dll
2011-08-04 02:51:54 13824 ------w- C:\Windows\SysWow64\agrscoin.dll
2011-08-04 02:51:49 -------- d-----w- C:\Program Files\LSI SoftModem
2011-08-04 02:51:44 -------- d-----w- C:\Windows\Options
2011-08-04 02:51:32 -------- d-----w- C:\Program Files\Synaptics
2011-08-04 02:49:27 -------- d-----w- C:\Program Files\ATI
2011-08-04 02:49:25 -------- d-----w- C:\Program Files (x86)\ATI Technologies
.
==================== Find3M ====================
.
2011-06-11 02:56:44 3134464 ----a-w- C:\Windows\System32\win32k.sys
2011-06-02 06:45:22 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-06-02 06:45:22 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-06-02 06:45:22 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-06-02 06:44:54 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-02 06:42:37 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-06-02 06:39:54 422400 ----a-w- C:\Windows\System32\KernelBase.dll
2011-06-02 06:35:56 338944 ----a-w- C:\Windows\System32\conhost.exe
2011-06-02 05:59:44 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-06-02 05:56:28 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-06-02 05:56:06 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-06-02 05:54:51 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-06-02 05:54:50 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-06-02 03:51:00 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-06-02 03:50:59 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-06-02 03:45:49 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-06-02 03:45:49 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-02 03:45:49 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-06-02 03:45:49 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-05-28 03:25:16 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-05-28 03:00:02 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 17:14:51.45 ===============
.